← Vulnerability feed

Vulnerability record · CVE-2018-5482 · published 4 March 2019

CVE-2018-5482: Netapp snapcenter server missing encryption vulnerability

NNetapp · Snapcenter Server

NetApp SnapCenter Server prior to 4.1 does not set the secure flag for a sensitive cookie in an HTTPS session which can allow the transmission of the cookie in plain text over an unencrypted channel.

5.3 CVSS 3.0 Medium EPSS 0.93% · top 41.0% CWE-311 · Missing encryption
5.3CVSS 3.0 base score, v2 5.0
0.93%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
4References
17 Jun 2026Last modified by NVD

Description

NetApp SnapCenter Server prior to 4.1 does not set the secure flag for a sensitive cookie in an HTTPS session which can allow the transmission of the cookie in plain text over an unencrypted channel.

CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2018-5482 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

6.1CVE-2020-11023jQuery DOM manipulation methods XSS via untrusted HTML option elementsjQuery versions 1.0.3 through before 3.5.0 execute untrusted code when HTML containing <option> elements from untrusted sources is passed to DOM mani…KEVEPSS 85%analysed9.8CVE-2018-8014Apache tomcat insecure default initialization vulnerabilityThe defaults settings for the CORS filter provided in Apache Tomcat 9.0.0.M1 to 9.0.8, 8.5.0 to 8.5.31, 8.0.0.RC1 to 8.0.52, 7.0.41 to 7.0.88 are ins…EPSS 21%8.8CVE-2017-15516Netapp snapcenter server cross-site request forgery vulnerabilityNetApp SnapCenter Server versions 1.1 through 2.x are susceptible to a Cross-Site Request Forgery (CSRF) vulnerability which could be used to cause a…EPSS 0.56%8.1CVE-2015-7887Netapp snapcenter server improper access control vulnerabilityNetApp SnapCenter Server 1.0 allows remote authenticated users to list and delete backups.EPSS 1.4%7.5CVE-2016-8610Openssl uncontrolled resource consumption vulnerabilityA denial of service flaw was found in OpenSSL 0.9.8, 1.0.1, 1.0.2 through 1.0.2h, and 1.1.0 in the way the TLS/SSL protocol defined processing of ALE…EPSS 40%7.3CVE-2016-1502Netapp snapcenter server improper authentication vulnerabilityNetApp SnapCenter Server 1.0 and 1.0P1 allows remote attackers to partially bypass authentication and then list and delete backups via unspecified ve…EPSS 1.6%7.2CVE-2017-15519Netapp snapcenter server improper authentication vulnerabilityVersions of SnapCenter 2.0 through 3.0.1 allow unauthenticated remote attackers to view and modify backup related data via the Plug-in for NAS File S…EPSS 1.2%6.5CVE-2020-14800Oracle mysql vulnerabilityVulnerability in the MySQL Server product of Oracle MySQL (component: Server: Security: Encryption). Supported versions that are affected are 8.0.21 …EPSS 1.4%

Source: NIST National Vulnerability Database (record CVE-2018-5482), CISA KEV, FIRST EPSS (scores of 2026-10-01). This page is refreshed as NVD updates the record.